PT-2025-11451 · Dcmtk+4 · Dcmtk+4

·

CVE-2025-2357

·

Published

2025-03-16

·

Updated

2025-09-10

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: DCMTK version 3.6.9
Description: A critical vulnerability was found in the dcmjpls JPEG-LS Decoder component of DCMTK, affecting unknown code and leading to memory corruption. The attack can be initiated remotely. The manipulation with the dcmjpls component can cause memory corruption.
Recommendations: To fix this issue, it is recommended to apply a patch, specifically the patch named 3239a7915, to DCMTK version 3.6.9. As a temporary workaround, consider disabling the dcmjpls JPEG-LS Decoder component until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8713
ALT-PU-2025-8855
BDU:2025-11441
CVE-2025-2357
DLA-4227-1
MGASA-2025-0117
OPENSUSE-SU-2025:14901-1

Affected Products

Alt Linux
Astra Linux
Dcmtk
Debian
Red Os